First published: Fri Apr 24 2015(Updated: )
Use-after-free vulnerability in the ff_h264_free_tables function in libavcodec/h264.c in FFmpeg before 2.3.6 allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted H.264 data in an MP4 file, as demonstrated by an HTML VIDEO element that references H.264 data.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
FFmpeg | <=2.3.5 | |
Debian GNU/Linux | =8.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-3417 has been classified as high severity due to its potential to cause denial of service and other unspecified impacts.
To fix CVE-2015-3417, upgrade FFmpeg to version 2.3.6 or later.
CVE-2015-3417 affects FFmpeg versions prior to 2.3.6 and Debian Linux 8.0.
CVE-2015-3417 is a use-after-free vulnerability stemming from improper handling of H.264 data.
Yes, CVE-2015-3417 can be exploited remotely through crafted H.264 data in an MP4 file.